Ghost Accounts Abuse GitHub API in Mass Recon Campaign

2026-07-12T19:24:03Z00497fc7494df544f48a47b4aff89c4e4bc7424ac71fa8b3ac5eae56f268e2fd
AI-hallucinationsAPI-abuseBlackCat/AlphvChina-linked-activity','India-linked-activity','Pakistan','Balo­Entra-IDGigaWiperGitHubGo-moduleHalluSquattingMicrosoft-365OktaPowerShellbotnetdead-dropghost-accountsmalicious-repositoriesmalwaremass-reconnaissancenation-statephishingransomwareransomware-negotiationsupply-chainvishingwiper

What happened

Collection of SecurityWeek stories covering multiple high-impact threats and developments: ghost accounts abusing the GitHub API for mass reconnaissance of organizations (repos and members); a network of ~200 malicious GitHub repositories using a Go module to stage PowerShell-based Windows malware via public dead-drops; GigaWiper—a backdoor with wiper, ransomware and multi-pass wiping capabilities—used for destructive system-level sabotage; Okta warnings of vishing campaigns that steer Microsoft 365 users to Entra ID phishing pages; ‘HalluSquatting’ attacks that weaponize AI hallucinations to達

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
00497fc7494df544f48a47b4aff89c4e4bc7424ac71fa8b3ac5eae56f268e2fd
Enrichment time
2026-07-12T19:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.